Top 25 OSINT Tools
- Biohazard

- 5 days ago
- 7 min read

OSINT Tools (Top 25)
This article / guide is on the top 25 OSINT tools for intelligence / information gathering available for you now to use.
Tool 1: Maltego
A graph-based link analysis and data visualization platform. Start with a domain, IP, email, or name, and Maltego runs transforms against 100+ data sources to map relationships — DNS records, social media profiles, WHOIS data, SSL certificates, and more. The visual graph makes it easy to spot connections between entities that would be invisible in raw data. The Community Edition (CE) is free with limitations; commercial licenses unlock more transforms. Essential for mapping an organization's full digital footprint and discovering infrastructure relationships.
Tool 2: Shodan
The search engine for internet-connected devices. While Google indexes web pages, Shodan indexes banners and metadata from every exposed service on every public IP — servers, routers, webcams, ICS/SCADA systems, databases, IoT devices. Use filters like port:, org:, country:, product:, os: to find exposed RDP, unauthenticated MongoDB instances, vulnerable industrial control systems, or a target's entire external attack surface. The CLI client and API make it scriptable for automated reconnaissance.
Tool 3: theHarvester
A command-line passive reconnaissance tool for email harvesting, subdomain discovery, and virtual host enumeration. Queries search engines (Google, Bing, Yahoo), PGP key servers, Shodan, Have I Been Pwned, LinkedIn, and certificate transparency logs — all passively, with no traffic sent directly to the target. Fast, lightweight, and ideal for the first 10 minutes of any engagement. Outputs clean lists of email addresses, subdomains, and IPs ready for further enumeration.
Tool 4: Recon-ng
A full-featured web reconnaissance framework with a modular architecture similar to Metasploit. Includes 100+ modules for DNS enumeration, contact scraping, credential harvesting, geolocation, port scanning, vulnerability discovery, and reporting. All results are stored in a built-in database, making correlation and reporting straightforward. Its marketplace lets you install community modules. Excellent for structured, repeatable recon workflows with documented output.
Tool 5: Spiderfoot
An automated OSINT framework that scans 200+ data sources from a single target input — IP, domain, email, or CIDR range. SpiderFoot runs automated reconnaissance across threat intelligence platforms, search engines, social media, DNS, certificate transparency, dark web sources, and more. Produces interactive correlation graphs and detailed CSV/HTML reports. The HX (premium) version adds real-time monitoring and team collaboration. A massive time-saver for initial target profiling.
Tool 6: Amass (OWASP)
The gold standard for subdomain enumeration and network mapping. Uses DNS brute-forcing, certificate transparency logs, search engine scraping, reverse DNS, web archives, and 50+ APIs to build a complete map of an organization's domain landscape. Amass doesn't just list subdomains — it resolves them, maps IP ranges, identifies ASNs, and visualizes the relationships. Deeply integrated with the OWASP project ecosystem. Indispensable for understanding the full scope of a target's external presence.
Tool 7: Sherlock
A lightweight Python tool that hunts for a single username across 300+ social networks, forums, and online platforms. Given a username, Sherlock checks hundreds of sites — Twitter, Instagram, Reddit, GitHub, TikTok, and obscure forums — and reports where accounts exist. Essential for tracking an individual's digital footprint, discovering alternate profiles, and building a target's online identity map. Fast, scriptable, and regularly updated with new platforms.
Tool 8: Holehe
Given an email address, Holehe checks whether an account exists on 100+ online services — without sending an email or alerting the target. It leverages password reset flows and registration endpoints that reveal whether an email is already registered. Results show which services a target uses (Spotify, Twitter, Dropbox, etc.), revealing their digital service footprint. Essential for profiling and discovering additional attack surface through password reset vectors.
Tool 9: PhoneInfoga
Advanced phone number reconnaissance and validation tool. Given a phone number, PhoneInfoga validates the number format, identifies the carrier and line type, checks if it's VoIP/landline/mobile, and scans for publicly associated footprints across search engines, social media, and breach databases. Useful for OSINT on individuals, verifying number validity before social engineering, and scanning for exposed phone-linked accounts.
Tool 10: Metagoofil
Extracts metadata from publicly available documents — PDFs, DOCX, XLSX, PPTX — discovered via Google dorking on a target domain. Metadata often contains usernames, real names, email addresses, software versions, internal file paths (revealing network share names and server hostnames), and author information. Deceptively simple but often yields high-value intelligence that is directly useful for credential attacks and network mapping.
Tool 11: Censys
A internet-wide asset discovery and monitoring platform that continuously scans every public IP. Like Shodan, but with a stronger focus on certificate transparency, TLS configurations, and historical data. Censys excels at discovering orphaned assets, expired certificates, and shadow IT — infrastructure the target organization may have forgotten about. The query language is expressive and the data refreshes frequently. Excellent for attack surface discovery and continuous monitoring.
Tool 12: Sublist3r
A fast and simple subdomain enumeration tool that queries search engines (Google, Yahoo, Bing, Ask, Baidu), VirusTotal, ThreatCrowd, DNSdumpster, and Netcraft. Written in Python and dead simple to use. While Amass is more comprehensive, Sublist3r is faster for quick reconnaissance and still catches subdomains that other tools miss through its diverse set of sources. Great as a first-pass subdomain sweep.
Tool 13: ffuf (Fuzz Faster U Fool)
A high-speed web fuzzer written in Go. Used for directory brute-forcing, virtual host discovery, parameter fuzzing, and POST data fuzzing. Filters by status codes, response size, word count, and regex patterns. Blisteringly fast compared to traditional tools like dirb or gobuster, and its filtering engine makes it far more precise. Essential for discovering hidden endpoints, admin panels, and API routes during web reconnaissance.
Tool 14: waybackurls
Extracts all URLs archived for a domain from the Wayback Machine. Given a domain, this tool pulls every historical URL the Internet Archive has ever saved — including old endpoints, forgotten API paths, exposed admin panels, dev servers, and sensitive files that may no longer be linked but are still accessible. Combined with tools like gau (getallurls) and waybackrobots, it builds an enormous historical URL catalogue. Piping these URLs into vulnerability scanners often finds forgotten attack surface.
Tool 15: gitrob / truffleHog
Repository secret-scanning tools. TruffleHog scans git repositories — both local and remote — for high-entropy strings (API keys, private keys, database credentials, tokens, passwords) across commit history. It detects secrets in real-time and via historical deep-scan. gitrob is its predecessor, specifically designed to scan GitHub organizations for sensitive files committed accidentally. Both are essential for the "secrets in code" side of OSINT — developers leak credentials and API keys into public repos constantly.
Tool 16: Photon
A fast, feature-rich web crawler designed specifically for OSINT. Given a URL, Photon crawls the entire site, extracting URLs (internal and external), email addresses, social media links, keys (API keys, Google API keys, AWS keys), JavaScript files, and custom regex matches. Output is organized into clean files per category. Excellent for rapidly mapping everything a website exposes — including secrets embedded in client-side JavaScript and HTML comments.
Tool 17: GHunt
A Google account reconnaissance tool. Given a Gmail address or Google ID, GHunt extracts the user's name, profile photos, connected YouTube channels, Google Maps reviews, Google Photos metadata (if exposed), and linked Google Plus/Workspace profiles. It leverages Google's own APIs to piece together a surprising amount of intelligence from a single email address. Ideal for profiling individuals and discovering digital footprints beyond what typical tools find.
Tool 18: Twint (Twitter Intelligence)
A Twitter scraping tool that bypasses the Twitter API entirely, scraping tweets directly without rate limits. Given a username, keyword, hashtag, or geolocation, Twint pulls complete tweet histories with timestamps, mentions, replies, and media. No API key required, no authentication, no rate limits. While Twitter/X has become increasingly hostile to scraping, Twint pioneered the approach and its capabilities (historical tweets, follower graphs, geolocated posts) remain essential OSINT techniques.
Tool 19: ExifTool
The definitive tool for reading, writing, and manipulating metadata across virtually every file format — images, PDFs, videos, audio, documents. For OSINT, ExifTool extracts geolocation coordinates from photos, camera model/serial numbers, software version strings, creator names, and modification timestamps. A single photo can reveal exactly where and when it was taken, what device was used, and who created the file. Indispensable for image and document intelligence.
Tool 20: H8mail
Email breach data checker. Given one or more email addresses, H8mail queries multiple breach databases and APIs (Have I Been Pwned, DeHashed, SnusBase, and local databases) to find associated breaches. It returns which services were breached, what data types were exposed (passwords, hashes, PII), and the breach date. Compile target emails via theHarvester, feed them into H8mail, and you know exactly which credentials to hunt for in public breach dumps.
Tool 21: DNSTwist
Domain name permutation engine. Given a domain, DNSTwist generates hundreds of typosquatting variants — character omission, repetition, replacement (lookalike characters), homoglyph attacks (Punycode), TLD variations, and hyphenation. Each variant is resolved to check if it's registered, who owns it, and what IP it points to. Used both offensively (identify phishing targets) and defensively (monitor for typosquatted domains impersonating your brand). Essential for phishing reconnaissance.
Tool 22: CloudFail
A tactical DNS reconnaissance tool that exploits misconfigured DNS to discover the real origin IP behind CloudFlare-protected websites. It queries search engines, DNS history databases (CrimeFlare), and DNSDumpster for historical DNS records of a domain, then tests each discovered IP to find the real server behind the CDN. Modern versions incorporate additional techniques like certificate transparency log analysis and subdomain brute-forcing to bypass CDN protection.
Tool 23: Buster (social-analyzer / socid-extractor)
A browser-extension and command-line tool that extracts social media profiles, email addresses, and phone numbers from web pages in real-time. As you browse a LinkedIn profile, Twitter feed, or any webpage, it identifies and collects every digital identifier present — usernames, profile URLs, email patterns, and phone formats. Faster than manual copy-paste for building a target's digital identity map during live browsing.
Tool 24: IVRE
An open-source network recon framework that imports data from Nmap, Zmap, Masscan, and passive DNS to build a searchable, browsable database of network intelligence. Think of it as self-hosted Shodan for your own scans. IVRE provides a web UI with filtering, visualization, and historical tracking of network assets. Useful when you need to run broad network scans and query the results as structured data rather than parsing raw XML.
Tool 25: OSINT Framework
A curated web directory (osintframework.com) that categorizes and links to hundreds of OSINT tools and resources by function — email lookup, username search, domain research, IP address analysis, social media discovery, geolocation, dark web sources, cryptocurrency tracing, vehicle identification, and more. Not a tool itself, but the definitive meta-resource for discovering which tool to use for any OSINT task. When you don't know what tool exists for a specific need, this is where you look.
Honorable Mentions
Gobuster — DNS, directory, and VHOST brute-forcing in Go. Faster than dirb, more features than ffuf for DNS mode.
DumpsterDiver — Scans local file systems for hardcoded secrets, passwords, tokens, and PII.
Masscan — The fastest internet-scale port scanner. Scan the entire IPv4 internet for a single port in under 6 minutes.
EyeWitness — Takes a URL list and generates screenshots of each page with server headers and response data. Quick visual recon of a massive list of subdomains.
Social Mapper — Facial recognition OSINT. Given a photo, it searches social media platforms for matching faces using automated browser sessions.
Little Brother — Passive DNS reconnaissance and monitoring tool. Tracks DNS changes over time for a domain.







Comments